PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

Consulting

AI Product Security Assessment

Schedule a focused technical conversation that scopes your AI product risk, identifies the right advisory track, and translates your needs into a practical engagement proposal.

Selected service

AI Product Security Assessment

The deeper 2–4 week assessment for AI-enabled products — typically the follow-on to an AI Launch Security Review, or when a system needs full architecture, data-flow, trust-boundary, model and provider dependency, RAG surface, tenant isolation, authorization, privacy, logging, SDLC, and evidence review.

Duration

Typical duration: 2–4 weeks, depending on scope.

Deliverables

5 implementation-grade outputs

Rate

Scoped after discovery

What we cover

  • System and trust-boundary map
  • Reproducible high-impact findings
  • Prioritized remediation backlog
  • Control and evidence gaps
  • Executive and engineering summaries

Scoping workflow

Collect the details before the call.

Use the service-specific intake below to collect the organization profile, stakeholders, systems, and files we need in advance. The same workspace data can later be managed from your client portal.

Structured intake

Turn this into a scoped engagement.

This form captures the organization details, stakeholders, systems, and assets we need before the scoping review. It saves into your client workspace so the same record can be updated later from your account area.

What we ask

  • Which AI systems, product features, or agents are in scope first?
  • Where do retrieval, tool use, and provider boundaries create the most uncertainty?
  • What evidence already exists, and what is still missing?
  • Which launch, customer, or incident deadline is driving the work?

What to upload

  • Architecture diagram or service map
  • AI feature inventory or application register
  • Auth, retrieval, and model-provider notes
  • Logs, traces, or screenshots from the current environment
  • Any questionnaires or trust-center language already in circulation

Organization profile

Project details

Stakeholders

Who should receive the proposal, notes, and next steps?

Add at least one stakeholder so we know who to include in the follow-up.

Uploads

Add files, screenshots, or text artifacts before the call.

No uploads yet. Screenshots, docs, questionnaire exports, and notes can all be added here.

Open client portal

Saving writes this draft into your workspace profile. Nothing has been saved yet.

What we cover in the call

  • Architecture and trust-boundary map
  • RAG, tenant-isolation, and authorization scope
  • Privacy, logging, and SDLC coverage
  • Evidence gaps
  • Recommended engagement format

Typical duration

30 minutes

If you’re preparing:

  • • A short summary of your AI program or feature.
  • • Key risk concerns or audit requirements.
  • • Current controls, telemetry, and team structure.